CVE-2025-43929

Name
CVE-2025-43929
Description
open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
https://github.com/kovidgoyal/kitty/commit/ce5cfdd9caf44c538af800a07162e1f49bd53c35
https://github.com/kovidgoyal/kitty/compare/v0.40.1...v0.41.0
https://ghostwriter.kde.org/documentation/#links
https://hitman.services/cve-2025-43929/
https://github.com/0xBenCantCode/CVE-2025-43929

Match rules

CPE URI Source package Min version Max version
kitty >= 0 < 0.41.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
kitty edge-community 0.40.0-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
kitty edge-community 0.39.1-r2 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
kitty edge-community 0.39.1-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
kitty edge-community 0.39.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
kitty edge-community 0.38.0-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
kitty edge-community 0.38.0-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
kitty edge-community 0.37.0-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
kitty 3.22-community 0.37.0-r5 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable